HP-UX AAA Server A.08.01 administrator's guide (T1428-90072, May 2010)

Table Of Contents
16 OATH Standards-Based OTP Authentication
IMPORTANT: The SecurID authentication is obsolete in this release of the HP-UX
AAA Server. The SecurID authentication can be replaced by Open AuTHentication
(OATH) standards-based One-Time Password (OTP) authentication. OATH is an
industry-wide collaboration to develop open-reference architecture for strong
authentication. The OATH standards-based OTP authentication solution supports
hardware and software tokens from multiple vendors.
This chapter introduces the Open AuTHentication (OATH) standards-based One-Time
Password (OTP) authentication. It also describes how to enable the HP-UX AAA Server
to provide OTP, and OTP and password (two-factor) authentication in different
deployment scenarios. The term OTP authentication is used throughout this document
to refer to the functionality that enables OTP authentication. The term two-factor
authentication is used for password and OTP authentication.
This chapter addresses the following topics:
OTP and OATH Overview
“HP-UX AAA Server and OATH Support” (page 180)
“Supported OTP Functions for RADIUS Standard Password (PAP) and MS-CHAP
v2” (page 182)
“Components Required to Configure OTP Authentication” (page 182)
“Configuring OTP Authentication on the HP-UX AAA Server ” (page 183)
“OTP Authentication Configuration Flowchart” (page 183)
“Basic or Typical Configuration” (page 186)
Advanced Configuration” (page 187)
Advanced OTP Authentication Configuration Concepts” (page 187)
Advanced Deployment Scenarios” (page 199)
“Predefined Mapping and Conversion Functions” (page 217)
“Sample Configuration Files” (page 217)
OTP and OATH Overview
Like a password, OTP can be used to authenticate the user to obtain access to a network.
OTP can be used alone or along with a password for authentication. Typically, OTP is
used for two-factor authentication. For example, in large organizations, VPN access
often requires the use of user-name, password, and OTP for remote user two-factor
authentication. Added security is provided when an OTP is used for authentication,
because a user must enter a different OTP each time to authenticate to a validation
server.
OTP and OATH Overview 179